Deploy ApyGuard
inside your network.
Use ApyGuard on-premise when API security testing, credentials, traffic data, scan evidence, and reports need to remain inside infrastructure controlled by your organization.
Deployment
VM packages on customer-managed servers
Connectivity
Internal APIs, gateways, and auth services
Secrets
Customer-managed tokens and test accounts
Access
Role-based team access and audit visibility
completed
Loaded private OpenAPI catalog
completed
Resolved internal gateway routes
completed
Validated auth profiles from secrets
completed
Started scheduled authenticated scan
Findings, evidence, credentials, and reports remain in your controlled environment.
01 / Setup Flow
From architecture review
to private scans.
Architecture review
Map API gateways, internal services, authentication flows, and network boundaries before deployment starts.
VM package deployment
Install ApyGuard packages on customer-managed virtual machines with controlled ingress and private network access.
Network settings setup
Configure hostnames, ports, firewall rules, and internal service reachability for the ApyGuard VM packages.
Scan orchestration
Schedule authenticated scans, CI checks, traffic analysis, and behavior profiling from inside your environment.
Operational handoff
Align logging, alert routing, update windows, and ownership so your team can run the platform confidently.
02 / Security Model
Keep sensitive testing
under your controls.
On-premise setup is designed for teams with private APIs, regulated environments, strict evidence-handling rules, or network boundaries that cloud-only tools cannot reach.
Data stays in your environment
API specs, traffic samples, credentials, scan evidence, and reports remain inside infrastructure you operate.
Private network reachability
Scan internal APIs, staging systems, VPN-only services, and restricted gateways without exposing them publicly.
Enterprise identity alignment
Use your existing identity, access, and approval model for users who manage scans and review findings.
Controlled update process
Coordinate version updates, maintenance windows, and release validation with your security and platform teams.
03 / Operating Model
Built for the teams
who own production risk.
Platform teams
- Run ApyGuard close to private APIs
- Control ingress, egress, and update windows
- Integrate logs with internal observability
Security teams
- Scan non-public API surfaces
- Keep evidence and findings in owned systems
- Review authenticated issues without data leaving the network
Engineering teams
- Use CI checks against private services
- Validate OpenAPI coverage before releases
- Track behavior drift across internal environments
Pair on-premise deployment with traffic analysis and behavior profiling to secure internal APIs, staging environments, and private production services from the same controlled installation.
What stays private
- API specifications and endpoint inventory
- Authentication credentials and test accounts
- Traffic samples, payloads, and response evidence
- Security findings, remediation notes, and reports
When to choose on-prem
- Your APIs are reachable only from private networks
- Security data cannot be processed by an external SaaS
- Your compliance process requires customer-operated systems
- Your team needs strict control over upgrades and retention
ApyGuard On-Prem
Talk through your
deployment requirements.
Share your network model, compliance needs, and API security goals. The ApyGuard team will help scope the right on-premise setup for your environment.